A little more info, but not alot. More monitoring.
Equally discovered PHPIDS, reading how it works. Im not sure this would have picked up on this attack vector, as it would have been legitimate traffic. Just rapidly used.
Would anyone care to put forward a solution to proactively tackle a similar script.
What I am specifically after, methods to know that this one computer ( keep it simple ) has sent x 1,000 requests in a short time ( ie to quick to be human ).
Before some of you lay the blame purely on AT&T for having poor code.
Other scenarios which are similar but different.
Perhaps we want to use this to throttle api requests, or to tackle a brute force attempt on the login.
But surely, as the "webapp" you can also revoke a users subscription.
I have been thinking about "recurring payment" with an agreed, "we the webapp" will cancel your paid access if you have been absent of the site "x days" or more likely 2 months.
Like many a member here, I am building something. In my case in PHP.
I have lovingly crafted ( wasted ) a system which is still in its infancy to handle a form of automated test driven development and from what I can see so far, the times I break it or discover a bug ( logic bug ) in my code later it is usually due to week tests.
Clearly I am not a large site like wordpress.com, a part of me thinks its the right thing to do. It certainly makes deploying a breeze and gives a little more "confidence" that the system didn't just fall over.
The sad part, at least in the PHP world, there are no libraries with an explanation on how best to use it with your site / application structure.
The database part is the biggest hiccup.
My solution is a duplicate database with no data.
First it confirms that the "fake db" matches the "real db" and warns if the table structure is different.
Then with my blank "fake db" using functions in my tests to "setup" and "destroy" I purposly build data to test with.
Once my site is operational, I will look to using live data in the "fake db" to simulate with real data. But so far it has been an interesting journey.
Clearly, TDD would become a bigger issue if you have to test sphinx/couchdb/mongodb etc setups but like with all creations its starts with a blank.php. ( in my case )
Not that this covers "Optimise for security".
But my test suite, after the first "test time" the test has been run, will warn if the "library","model", "controller" it is linked to has been altered without the "test" file changing, which at least warns me to the idea that maybe I need to refine my test.
All very padantic, but reading from the side lines of patio11, I can't help but see logic in "automating" things to make your life easier, more efficent and less likely to add human error into the equation.
I leave with what I consider a valid point.
Once upon a time, people looked at the "MVC" approach as time consuming and wasteful. At least from my understanding of watching the web evolve from the earlier days.
The downside of my excitement over this url is as of 28th April in the afternoon it is still claiming it will be released on the 27th. A shame, I was curious to see what and how they tested peoples cybersecurity skills.
Minusing the already growing snarkey comments, i too am at a loss, probably as i have never heard of them secondly their website forces me to stay in the iPhone version.
What am i missing?
Based on the blog post they mentioned igoogle ahead of games. Could it be linked to creating a more igoogle game marketplace.
Also couldnt help but notice how a game for igoogle would be constrained to small dimensions, just like those of a mobile.
I like to do my fair share of running, and found his comment on "marathon runners" having a suspiciously high cancer rate. Curious and wanting to know more...
Granted I have only skimmed over the following ( ie this stuff is hot off the internet press )
http://cebp.aacrjournals.org/content/17/1/183.full
This is a full text article discussing how regular exercise whici I consider running and marathon training to be part of, is useful in the fight against colon cancer, yet they are not 100% sure why.
I too am a huge fan of SQL, what mysql and postgres has given to the world and how it has inspired and set seeds in many of us to use open source, contribute to open source.
I am dipping my toes into couchdb, just to see what all the noise is about.
Still getting my head around map,reduce and the fact im writing in javascript. All that aside the biggest exciting factor for me.
It is so much easier to write custom functions for it than SQL. ( Mysql, and yes I only tried via phpmyadmin )
For those of you who dont know, the IPL is a cricket tournament in India.
Enough of cricket.
This is a huge event for youtube, its infrastructure and its a glimpse into where we might be going with sports events in the future.
Just had an ad, a friend in another country, saw a different ad to me.
Equally, maybe its just in this instance, but the "Official Community" is linked to googles social network, even tho they are showing live streaming of twitter.
As you can tell, im quite excited about this.
Am I alone in thinking this is amazing use of technologies.
b) Highlight the fact that search engines are allowed to see free content.
If its "a)", I disagree with your suggestion.
If its "b)". I agree, I find it highly annoying when you click on a link to discover the part you want to read is hidden from you behind a pay wall. Search engines should show what we see the non paying public, furthermore I believe google doesnt like the addition of words to raise the rank of the page, sites which do this should be penalised for this behaviour. Which is what happens when you give google access to "fuller" data.
What i Think your doing is dangling a "carrot on a stick".
Just the same as many mobile companies offering you free calls or sms. They/you want them comfortable with your product, used to using it. Then the barrier to going past the free quota is a little lower.
I equally like to a point how your tracking it via excel, instead of building a system for hours. Once proven it might aid growth of revenue, then i see the system being built.
Even if the above is not correct for you, it has given me food for thought and helped solidify a few liquid thoughts.
I have a shared plan on mediatemple. I am not a ruby man yet am 100% you can run rails. Then you can demonstrate both your ruby skills and your new found php skills.
Im still thinking of my own thoughts on this topic.
Whilst I try and grapple with this notion and potential implications I would like to ask a question of my fellow HN'ers. ( especially those who have posted so far )
Have you been to university?
Do you have a degree or something else from a university?
I ask these questions as I think its important to get a little background of the person who is posting there views.
I do have a degree in "Information Technology no less Majoring in Data communications".
My gut feeling is, there will always be a place for universities. I further believe there will be a huge growth market in self paced study via the internet which will not be linked primarily to universities. Further more, I want to believe that universities will be geared more towards those who are able to "do it for themselves".
"do it for themselves" - I believe will get taught / inspired at school ( high school etc ) via social networks and via social / console games to a point.
I have a few friends in different fields of research and in the biotech field. I sent them a link from sciencedaily, after thanking me for the link. They politely informed me that sciencedaily is not a worth while publication and therefore deem the information from it not so exciting / important.
You could say they are being snobbish maybe even elitist. But as mentioned in the comments, this is not the first time a post to there has had words like "misleading" etc.
What if we had a peer review, prestigious website where you could submit your articles for publishing in the IT world?
Equally, does "snobbishness" exist already in peer review sites for the IT world already?
Your name is incredibly close to a user here in HN who has the website http://www.lingq.com/. Is he working with you on this, or is this just poor creativity on your behalf for a name?
Not coming across in a negative way, at first I thought his site had a revamp. Now im just confused.
Im more curious about how many bank accounts are out there with 6 figure + sums in them which haven't been touched for years.
Equally makes you wonder how many of the banks are enjoying profits from such accounts when clearly it must be suspected that they are dodgy / tarnished or criminal in some way.
A little more info, but not alot. More monitoring.
Equally discovered PHPIDS, reading how it works. Im not sure this would have picked up on this attack vector, as it would have been legitimate traffic. Just rapidly used.